What problem does it solve? Juniper SRX ADVPN deployments fail in non-obvious ways: PSK authentication that cannot commit, IKE_AUTH loops over NAT-T, and a dynamic-gateway certificate defect that rejects every spoke with "No public key found". This Skill pins the agent to field-verified Junos syntax and known workarounds so ADVPN designs actually commit and shortcuts actually form. ## Core Features & Use Cases - ADVPN design and configuration: Produces complete hub (suggester) and spoke (partner) configurations with multipoint st0, OSPF p2mp with dynamic-neighbors, and certificate-based IKEv2. - PKI enrollment guidance: Walks through keypair generation, CSR signing, and certificate loading, including the chassis-cluster RG0-primary gotcha. - Troubleshooting matrix: Maps symptoms like NAT-T 4500 retransmits, missing shortcuts, and the vSRX3 dynamic-gateway "No public key found" defect to root causes and fixes. - Use Case: A network engineer building a 12-branch ADVPN overlay on vSRX3 uses this Skill to generate the hub and spoke configs, enroll certificates, and diagnose why spoke IKE_AUTH fails on the dynamic gateway. ## Quick Start Use the srx-advpn skill to design an ADVPN hub-and-spoke deployment with certificate authentication and OSPF over a multipoint st0 overlay.